For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Your Coverbase representative turns on the third-party lifecycle features, including these routes, for your organization.
cbegm_...) is one piece of business with a vendor: the service a Transaction Owner is buying. This API lets a GRC, orchestration or reporting tool read engagements, their status and risk level, and the services and contracts they cover. It is read-only.
These routes are
/v1/engagement-records. The similar-looking /v1/engagements paths are dashboard routes and are not part of the public API. While the third-party lifecycle features are off for your organization, every route here returns 404 with not_enabled.ak_* key or an OAuth token, and need permission to read vendors. See API conventions for shared behavior.
List engagement records
GET
GET /v1/engagement-records{ "items": [...], "total", "limit", "offset" }.
string
Only engagements with this vendor (
cbvndr_...).integer
default:"50"
1 to 200.
integer
default:"0"
0 or more.
cURL
Get an engagement record
GET
GET /v1/engagement-records/{engagement_id}404 engagement_not_found.
The engagement record object
string | null
The label of the engagement’s status in your organization’s status list.
string | null
The group the status belongs to:
unstarted, started, completed or canceled. It does not change when your organization renames statuses, so use it, not the label, in integration logic.string | null
The name of the engagement’s inherent risk level.
string | null
The name of the engagement’s residual risk level.
string[]
The vendor services (
cbsvc_...) the engagement covers.string[]
The contract records linked to the engagement.